Azure AI Foundry
The Azure AI Foundry connector gives Quilr read-only visibility into the agents, models, and agent activity running in your Azure AI Foundry projects. You register a Microsoft Entra application in your own tenant, grant it three Azure roles, and choose which subscriptions and projects Quilr watches. A background sync then keeps AI Inventory, the Overview dashboard, and — where you opt in — Conversations up to date.
- Integration Type: Microsoft Entra service principal (OAuth 2.0 client credentials)
- Vendor: Microsoft
This connector is separate from Azure Cloud. Azure Cloud uses an interactive Microsoft sign-in for broad Azure AI and Machine Learning Studio asset discovery. Azure AI Foundry uses a customer-owned service principal and adds per-project control over agent inventory and agent conversation history.
How It Works
- You create a Microsoft Entra app registration and client secret in your own tenant.
- You grant that app three Azure roles at subscription scope.
- You enter the tenant ID, client ID, and client secret in Quilr.
- You select the Azure subscriptions Quilr should monitor.
- You enable Inventory and, optionally, Conversations for each discovered Foundry project.
- A background worker signs in as that service principal, pulls data for the enabled projects, and surfaces the results across the platform.
Quilr acts only as a reader. The connector never creates, modifies, or deletes Azure resources.
Before You Start
You need:
- An Azure subscription that contains at least one Azure AI Foundry project.
- Permission in Microsoft Entra ID to create an app registration and a client secret (Application Administrator, Cloud Application Administrator, or equivalent).
- Permission to assign Azure roles at subscription scope (Owner or User Access Administrator).
- Integration permissions in Quilr, with update access if you are editing an existing connection.
Required Azure Permissions
The connector authenticates as a customer-owned Entra service principal using the OAuth 2.0 client-credentials flow. It is not a managed identity and does not use a raw API key.
Assign all three roles to the app registration at subscription scope, for every subscription you plan to monitor.
The credentials are validated against the API audiences the connector needs:
- Azure Resource Manager (
management.azure.com) - Azure AI Foundry (
ai.azure.com) - Azure Machine Learning (
ml.azure.com) - Azure Cognitive Services (
cognitiveservices.azure.com) - Log Analytics (
api.loganalytics.io)
Azure AI Foundry User is a broad built-in role. Among other rights, it can list Cognitive Services keys. Quilr only ever performs read operations with this service principal, but you should review the role against your own least-privilege standards before assigning it, and scope it to only the subscriptions you intend to monitor.
Setup
Setup is a four-step wizard. You can leave and return to it; completed steps are preserved.
Step 1 — Prepare
Complete this step in the Azure portal or Azure CLI:
-
In Microsoft Entra ID, create a new app registration for Quilr.
-
Copy the Directory (tenant) ID and Application (client) ID from the app's overview page.
-
Under Certificates & secrets, create a new client secret and copy its value immediately. Azure shows the secret only once. Note its expiry date.
-
Copy the
az role assignment createsnippet generated on this step and run it for each subscription you want to monitor. It grants the three required roles at subscription scope:az role assignment create \
--assignee <application-client-id> \
--role "Reader" \
--scope /subscriptions/<subscription-id>
az role assignment create \
--assignee <application-client-id> \
--role "Azure AI Foundry User" \
--scope /subscriptions/<subscription-id>
az role assignment create \
--assignee <application-client-id> \
--role "Log Analytics Reader" \
--scope /subscriptions/<subscription-id>Use the snippet shown in the wizard rather than this example — it is pre-filled for your connection.
Role assignments can take a few minutes to propagate before the connector can see a subscription.
Step 2 — Credentials
Enter the following in Quilr:
The credentials are submitted once and validated against the required audiences. If that validation fails outright — for example, an invalid tenant, client ID, or secret — the wizard reports which audience it could not reach. Missing role assignments do not fail this step. They show up instead as incomplete readiness indicators per subscription in Step 3.
Step 3 — Subscriptions
Quilr lists the Azure subscriptions the service principal can see and shows a readiness indicator for each one, covering whether Management, Foundry, and Log Analytics access is actually present.
- Review the readiness indicators.
- Select the subscriptions you want Quilr to monitor.
- Fix any missing role assignment in Azure and re-check readiness if a subscription is incomplete.
A subscription with partial readiness can still be selected, but the data that depends on the missing access will not be collected.
Step 4 — Projects
Quilr discovers the Foundry projects inside the selected subscriptions and lists them with two independent switches:
- Inventory — collects asset metadata for the project.
- Conversations — collects agent thread content for the project. Inventory must be enabled first.
Turn on only what each project needs, then finish the wizard. Use Refresh projects at any time to run an on-demand sync and pick up newly created projects.
Data Collection Options
The two switches are deliberately separate because they collect very different kinds of data.
Inventory
When Inventory is on, the connector reads the project through the Foundry or Azure OpenAI APIs — whichever generation the project uses — and collects:
- Assistants (agents) and their configured tools
- Model deployments, including the assigned content-safety (RAI) policy name
- Files
- Vector stores
Conversations
When Conversations is on, the connector additionally collects full agent thread history: messages, runs, and run steps, including prompts, tool calls, and run outcomes.
Conversations is an explicit, per-project opt-in because it retrieves conversation content rather than metadata. Enable it only for the projects where you need agent-level activity history.
Where The Data Appears
AI Inventory
Inventory-enabled projects produce these asset types in AI Inventory:
Conversations
Conversation-enabled projects appear in the Conversations view as agent thread history — prompts, tool calls, and run outcomes.
Conversation data from this connector does not create entries in Findings. The closest equivalent to a finding is a failed run outcome, which is visible on the thread itself. Content-safety and RAI policy information is inventory metadata attached to the Model asset, not part of the conversation pull.
Overview Dashboard
The Azure Foundry estate tile on the Overview dashboard shows:
- Whether the connection is configured and ready
- Project count
- Agent count
- Active applications — projects with activity in the selected time range
- Total interactions
- A top-applications list with name and interaction count
The tile is scoped to conversation-enabled projects only. Projects with Inventory alone contribute assets to AI Inventory but do not appear in these activity metrics.
Sync Behavior And Status
The connector runs an hourly bounded sweep of the enabled projects: each connection resyncs about once an hour after a successful run. If a sync fails, that connection retries after 5 minutes rather than waiting for the next hourly window. You can also trigger an immediate sync with Refresh projects in the wizard's Projects step.
Connection status
Sync status
Per-project status
Credential Handling
- The client secret is encrypted at rest and keyed to the scope of that specific connection.
- The secret is never returned by Quilr once accepted. It is write-only from the console's perspective — you can replace it, but you cannot read it back.
- Rotate the secret in Azure before it expires, then re-enter the new value in the Credentials step. An expired secret puts the connection into Action required.
Troubleshooting
What This Integration Does
- Discovers Azure AI Foundry projects across the subscriptions you select.
- Inventories agents, agent tools, model deployments, files, and vector stores.
- Records each model deployment's content-safety (RAI) policy as asset metadata.
- Collects agent thread, message, run, and run-step history for projects you explicitly opt in.
- Surfaces Foundry estate size and agent activity on the Overview dashboard.
- Performs read operations only, using a service principal you own and can revoke at any time.